It’s Parliamentary: KeyBoy and the targeting of the Tibetan Community
released on 2016-11-17 @ 07:30:55 PM
In this report we track a malware operation targeting members of the Tibetan Parliament over August and October 2016.
The operation uses known and patched exploits to deliver a custom backdoor known as KeyBoy.
We analyze multiple versions of KeyBoy revealing a development cycle focused on avoiding basic antivirus detection.
This operation is another example of a threat actor using “just enough” technical sophistication to exploit a target.